DARK Caracal, a Lebanon-linked cyber-espionage group, has enhanced its capabilities with a new malware framework named GoCaracal, designed for data theft and maintaining access to compromised systems. Discovered by researchers at Arctic Wolf during an investigation into a Venezuelan intrusion, GoCaracal functions in two variations: a lightweight version for initial access and a more robust version for intelligence gathering.
The malware utilizes a blockchain-based backup to ensure resilience if its primary command-and-control (C2) servers are compromised. Dark Caracal has a history of targeting diverse groups including military, government, and journalists since at least 2012, employing tactics like phishing and malicious applications. The group has recently been active in Latin America, demonstrating sophistication in maintaining stealthy invasions for future intelligence exploitation.